name: Deploy k8s Infra on: workflow_dispatch: push: branches: - main paths: - 'k8s-infra/**' - '.gitea/workflows/**' pull_request: branches: - main paths: - 'k8s-infra/**' - '.gitea/workflows/**' jobs: preview: name: Pulumi Preview runs-on: ubuntu-latest if: github.event_name == 'pull_request' steps: - name: Checkout Code uses: actions/checkout@v4 - name: Setup Node.js uses: actions/setup-node@v4 with: node-version: '24' - name: Restore Stack Config run: echo "${{ secrets.K8S_INFRA_PULUMI_DEV_YAML }}" | base64 -d > k8s-infra/Pulumi.dev.yaml - name: Install Helm uses: azure/setup-helm@v4 - name: Install Dependencies run: npm ci working-directory: k8s-infra - name: Preview uses: pulumi/actions@v5 with: command: preview stack-name: dev work-dir: k8s-infra cloud-url: ${{ secrets.PULUMI_BACKEND_URL }} env: PULUMI_CONFIG_PASSPHRASE: ${{ secrets.PULUMI_CONFIG_PASSPHRASE }} deploy: name: Pulumi Deploy runs-on: ubuntu-latest if: github.event_name == 'push' || github.event_name == 'workflow_dispatch' steps: - name: Checkout Code uses: actions/checkout@v4 - name: Setup Node.js uses: actions/setup-node@v4 with: node-version: '24' - name: Restore Stack Config run: echo "${{ secrets.K8S_INFRA_PULUMI_DEV_YAML }}" | base64 -d > k8s-infra/Pulumi.dev.yaml - name: Install Helm uses: azure/setup-helm@v4 - name: Install Dependencies run: npm ci working-directory: k8s-infra - name: Refresh State uses: pulumi/actions@v5 with: command: refresh stack-name: dev work-dir: k8s-infra cloud-url: ${{ secrets.PULUMI_BACKEND_URL }} env: PULUMI_CONFIG_PASSPHRASE: ${{ secrets.PULUMI_CONFIG_PASSPHRASE }} - name: Deploy uses: pulumi/actions@v5 with: command: up stack-name: dev work-dir: k8s-infra cloud-url: ${{ secrets.PULUMI_BACKEND_URL }} env: PULUMI_CONFIG_PASSPHRASE: ${{ secrets.PULUMI_CONFIG_PASSPHRASE }}